WorksheetsTest blanc
Total questions: 20
Worksheet time: 15mins
Cybersecurity activities should be coordinated by:
Representatives from different parts of the organization with relevant roles and job functions
The chief information security officer
The cybersecurity program manager
“Level of risk” is defined with the following statement
Magnitude of a risk expressed in terms of the potential vulnerabilities and the threats that they possess
List of risks with value levels assigned
Magnitude of a risk expressed in terms of the combination of consequences and their likelihood
The risk that remains after the implementation of controls aiming to reduce the inherent risk is defined as
Treated risk
Residual risk
Avoided risk
Monitoring systems which do not respond to anything against incoming packets found within the Darknet IP domains refers to
Black hole monitoring
White hole monitoring
Gray hole monitoring
Please determine the correct definition of threats in the cyberspace
Potential cause of an unwanted incident, which may result in harm to a system, individual or organization
Weakness of an asset or control that can be exploited
Effect of uncertainty on objectives
The expression of the intent of the organization to treat the risks identified and/or to comply with requirements of organizational security is the objective of
Cybersecurity program
Information security program
Cyberspace program
Which of the risk treatment options the organization is adopting, in the scenario when it has recently conducted a risk assessment of their IT systems and decided to cancel the e-commerce activity to eliminate the risk of an accidental phishing threat?
Risk Modification
Risk Elimination
Risk Avoidance
which of the following is a type of malware?
Worm
Ransomwar
Virus
DoS
DDoS
Which of the risk treatment options the organization is adopting, in the scenario when it has recently conducted a risk assessment of their IT systems and decided to implement a new data loss prevention system to reduce the likelihood of an accidental data breach?
Risk Modification
Risk Retention
Risk Avoidance
Individual or organization having a right, share, claim or interest in a system or in its possession of characteristics that meet their needs and expectations is the definition of:
Stakeholder
Consumers
Providers
Which tools are more suitable to control network services accessing the user systems?
Personal firewalls
HIDS
Personal firewalls and HIDs
Establishing a system for information sharing and coordination:
Helps in preparing and responding to legal and regulatory requirements
Helps in preparing and responding to cybersecurity events and incidents
Helps in preparing and responding to customer complaints and requests
Visibility of changes and the emerging security incident taking place without the need for the operators to read the details of each event as it emerges can be improved through:
Data standardization
Data visualization
Telephone communication
A process that defines the dangers that threat an organization refers to:
Information security
Disaster recovery
Business continuity
Anything that has a value to an individual, an organisation or a government.
information
information asset
asset
Which of the following should be involved in the cybersecurity program?
Business functions
IT related functions
Business and IT-related functions
Why is it important for the cybersecurity program manager to understand the business process of the organization?
It is the conduct of the process that exposes the organization to numerous security risks
The cybersecurity program manager’s responsibilities should focus on the understanding of ICT related process only
The risk manager should analyze and understand the nature of these processes
Which of the following controls aims to discourage the appearance of the problems?
Detective control
Preventive Control
Corrective Control
While auditing the security level of an organization, we noticed that all employees' data are unencrypted. What's the possible threat in this case?
Virus
Loss of information
information theft
Which of the following does the process of risk treatment involve?
Selecting one or more options for modifying risks, and implementing these options
Selecting one or more options for eliminating risks, and implementing these options
Selecting one or more options for analyzing risks, and implementing these options
